mirror of
https://github.com/opencontainers/umoci.git
synced 2026-02-05 09:45:50 +01:00
build(deps): bump github.com/opencontainers/runtime-spec
Bumps [github.com/opencontainers/runtime-spec](https://github.com/opencontainers/runtime-spec) from 1.2.1 to 1.3.0. - [Release notes](https://github.com/opencontainers/runtime-spec/releases) - [Changelog](https://github.com/opencontainers/runtime-spec/blob/main/ChangeLog) - [Commits](https://github.com/opencontainers/runtime-spec/compare/v1.2.1...v1.3.0) --- updated-dependencies: - dependency-name: github.com/opencontainers/runtime-spec dependency-version: 1.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
This commit is contained in:
2
go.mod
2
go.mod
@@ -33,7 +33,7 @@ require (
|
||||
github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826
|
||||
github.com/opencontainers/go-digest v1.0.0
|
||||
github.com/opencontainers/image-spec v1.1.1
|
||||
github.com/opencontainers/runtime-spec v1.2.1
|
||||
github.com/opencontainers/runtime-spec v1.3.0
|
||||
github.com/rootless-containers/proto/go-proto v0.0.0-20230421021042-4cd87ebadd67
|
||||
github.com/stretchr/testify v1.11.1
|
||||
github.com/urfave/cli v1.22.12
|
||||
|
||||
4
go.sum
4
go.sum
@@ -75,8 +75,8 @@ github.com/opencontainers/go-digest v1.0.0 h1:apOUWs51W5PlhuyGyz9FCeeBIOUDA/6nW8
|
||||
github.com/opencontainers/go-digest v1.0.0/go.mod h1:0JzlMkj0TRzQZfJkVvzbP0HBR3IKzErnv2BNG4W4MAM=
|
||||
github.com/opencontainers/image-spec v1.1.1 h1:y0fUlFfIZhPF1W537XOLg0/fcx6zcHCJwooC2xJA040=
|
||||
github.com/opencontainers/image-spec v1.1.1/go.mod h1:qpqAh3Dmcf36wStyyWU+kCeDgrGnAve2nCC8+7h8Q0M=
|
||||
github.com/opencontainers/runtime-spec v1.2.1 h1:S4k4ryNgEpxW1dzyqffOmhI1BHYcjzU8lpJfSlR0xww=
|
||||
github.com/opencontainers/runtime-spec v1.2.1/go.mod h1:jwyrGlmzljRJv/Fgzds9SsS/C5hL+LL3ko9hs6T5lQ0=
|
||||
github.com/opencontainers/runtime-spec v1.3.0 h1:YZupQUdctfhpZy3TM39nN9Ika5CBWT5diQ8ibYCRkxg=
|
||||
github.com/opencontainers/runtime-spec v1.3.0/go.mod h1:jwyrGlmzljRJv/Fgzds9SsS/C5hL+LL3ko9hs6T5lQ0=
|
||||
github.com/pkg/errors v0.8.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
|
||||
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
|
||||
166
vendor/github.com/opencontainers/runtime-spec/specs-go/config.go
generated
vendored
166
vendor/github.com/opencontainers/runtime-spec/specs-go/config.go
generated
vendored
@@ -31,6 +31,8 @@ type Spec struct {
|
||||
VM *VM `json:"vm,omitempty" platform:"vm"`
|
||||
// ZOS is platform-specific configuration for z/OS based containers.
|
||||
ZOS *ZOS `json:"zos,omitempty" platform:"zos"`
|
||||
// FreeBSD is platform-specific configuration for FreeBSD based containers.
|
||||
FreeBSD *FreeBSD `json:"freebsd,omitempty" platform:"freebsd"`
|
||||
}
|
||||
|
||||
// Scheduler represents the scheduling attributes for a process. It is based on
|
||||
@@ -170,7 +172,7 @@ type Mount struct {
|
||||
// Destination is the absolute path where the mount will be placed in the container.
|
||||
Destination string `json:"destination"`
|
||||
// Type specifies the mount kind.
|
||||
Type string `json:"type,omitempty" platform:"linux,solaris,zos"`
|
||||
Type string `json:"type,omitempty" platform:"linux,solaris,zos,freebsd"`
|
||||
// Source specifies the source path of the mount.
|
||||
Source string `json:"source,omitempty"`
|
||||
// Options are fstab style mount options.
|
||||
@@ -236,6 +238,8 @@ type Linux struct {
|
||||
Namespaces []LinuxNamespace `json:"namespaces,omitempty"`
|
||||
// Devices are a list of device nodes that are created for the container
|
||||
Devices []LinuxDevice `json:"devices,omitempty"`
|
||||
// NetDevices are key-value pairs, keyed by network device name on the host, moved to the container's network namespace.
|
||||
NetDevices map[string]LinuxNetDevice `json:"netDevices,omitempty"`
|
||||
// Seccomp specifies the seccomp security settings for the container.
|
||||
Seccomp *LinuxSeccomp `json:"seccomp,omitempty"`
|
||||
// RootfsPropagation is the rootfs mount propagation mode for the container.
|
||||
@@ -249,6 +253,8 @@ type Linux struct {
|
||||
// IntelRdt contains Intel Resource Director Technology (RDT) information for
|
||||
// handling resource constraints and monitoring metrics (e.g., L3 cache, memory bandwidth) for the container
|
||||
IntelRdt *LinuxIntelRdt `json:"intelRdt,omitempty"`
|
||||
// MemoryPolicy contains NUMA memory policy for the container.
|
||||
MemoryPolicy *LinuxMemoryPolicy `json:"memoryPolicy,omitempty"`
|
||||
// Personality contains configuration for the Linux personality syscall
|
||||
Personality *LinuxPersonality `json:"personality,omitempty"`
|
||||
// TimeOffsets specifies the offset for supporting time namespaces.
|
||||
@@ -430,7 +436,7 @@ type LinuxCPU struct {
|
||||
// LinuxPids for Linux cgroup 'pids' resource management (Linux 4.3)
|
||||
type LinuxPids struct {
|
||||
// Maximum number of PIDs. Default is "no limit".
|
||||
Limit int64 `json:"limit"`
|
||||
Limit *int64 `json:"limit,omitempty"`
|
||||
}
|
||||
|
||||
// LinuxNetwork identification and priority configuration
|
||||
@@ -491,6 +497,12 @@ type LinuxDevice struct {
|
||||
GID *uint32 `json:"gid,omitempty"`
|
||||
}
|
||||
|
||||
// LinuxNetDevice represents a single network device to be added to the container's network namespace
|
||||
type LinuxNetDevice struct {
|
||||
// Name of the device in the container namespace
|
||||
Name string `json:"name,omitempty"`
|
||||
}
|
||||
|
||||
// LinuxDeviceCgroup represents a device rule for the devices specified to
|
||||
// the device controller
|
||||
type LinuxDeviceCgroup struct {
|
||||
@@ -678,6 +690,32 @@ type WindowsHyperV struct {
|
||||
UtilityVMPath string `json:"utilityVMPath,omitempty"`
|
||||
}
|
||||
|
||||
// IOMems contains information about iomem addresses that should be passed to the VM.
|
||||
type IOMems struct {
|
||||
// Guest Frame Number to map the iomem range. If GFN is not specified, the mapping will be done to the same Frame Number as was provided in FirstMFN.
|
||||
FirstGFN *uint64 `json:"firstGFN,omitempty"`
|
||||
// Physical page number of iomem regions.
|
||||
FirstMFN *uint64 `json:"firstMFN"`
|
||||
// Number of pages to be mapped.
|
||||
NrMFNs *uint64 `json:"nrMFNs"`
|
||||
}
|
||||
|
||||
// Hardware configuration for the VM image
|
||||
type HWConfig struct {
|
||||
// Path to the container device-tree file that should be passed to the VM configuration.
|
||||
DeviceTree string `json:"deviceTree,omitempty"`
|
||||
// Number of virtual cpus for the VM.
|
||||
VCPUs *uint32 `json:"vcpus,omitempty"`
|
||||
// Maximum memory in bytes allocated to the VM.
|
||||
Memory *uint64 `json:"memory,omitempty"`
|
||||
// Host device tree nodes to passthrough to the VM.
|
||||
DtDevs []string `json:"dtdevs,omitempty"`
|
||||
// Allow auto-translated domains to access specific hardware I/O memory pages.
|
||||
IOMems []IOMems `json:"iomems,omitempty"`
|
||||
// Allows VM to access specific physical IRQs.
|
||||
Irqs []uint32 `json:"irqs,omitempty"`
|
||||
}
|
||||
|
||||
// VM contains information for virtual-machine-based containers.
|
||||
type VM struct {
|
||||
// Hypervisor specifies hypervisor-related configuration for virtual-machine-based containers.
|
||||
@@ -686,6 +724,8 @@ type VM struct {
|
||||
Kernel VMKernel `json:"kernel"`
|
||||
// Image specifies guest image related configuration for virtual-machine-based containers.
|
||||
Image VMImage `json:"image,omitempty"`
|
||||
// Hardware configuration that should be passed to the VM.
|
||||
HwConfig *HWConfig `json:"hwconfig,omitempty"`
|
||||
}
|
||||
|
||||
// VMHypervisor contains information about the hypervisor to use for a virtual machine.
|
||||
@@ -828,23 +868,41 @@ type LinuxSyscall struct {
|
||||
type LinuxIntelRdt struct {
|
||||
// The identity for RDT Class of Service
|
||||
ClosID string `json:"closID,omitempty"`
|
||||
|
||||
// Schemata specifies the complete schemata to be written as is to the
|
||||
// schemata file in resctrl fs. Each element represents a single line in the schemata file.
|
||||
// NOTE: This will overwrite schemas specified in the L3CacheSchema and/or
|
||||
// MemBwSchema fields.
|
||||
Schemata []string `json:"schemata,omitempty"`
|
||||
|
||||
// The schema for L3 cache id and capacity bitmask (CBM)
|
||||
// Format: "L3:<cache_id0>=<cbm0>;<cache_id1>=<cbm1>;..."
|
||||
// NOTE: Should not be specified if Schemata is non-empty.
|
||||
L3CacheSchema string `json:"l3CacheSchema,omitempty"`
|
||||
|
||||
// The schema of memory bandwidth per L3 cache id
|
||||
// Format: "MB:<cache_id0>=bandwidth0;<cache_id1>=bandwidth1;..."
|
||||
// The unit of memory bandwidth is specified in "percentages" by
|
||||
// default, and in "MBps" if MBA Software Controller is enabled.
|
||||
// NOTE: Should not be specified if Schemata is non-empty.
|
||||
MemBwSchema string `json:"memBwSchema,omitempty"`
|
||||
|
||||
// EnableCMT is the flag to indicate if the Intel RDT CMT is enabled. CMT (Cache Monitoring Technology) supports monitoring of
|
||||
// the last-level cache (LLC) occupancy for the container.
|
||||
EnableCMT bool `json:"enableCMT,omitempty"`
|
||||
// EnableMonitoring enables resctrl monitoring for the container. This will
|
||||
// create a dedicated resctrl monitoring group for the container.
|
||||
EnableMonitoring bool `json:"enableMonitoring,omitempty"`
|
||||
}
|
||||
|
||||
// EnableMBM is the flag to indicate if the Intel RDT MBM is enabled. MBM (Memory Bandwidth Monitoring) supports monitoring of
|
||||
// total and local memory bandwidth for the container.
|
||||
EnableMBM bool `json:"enableMBM,omitempty"`
|
||||
// LinuxMemoryPolicy represents input for the set_mempolicy syscall.
|
||||
type LinuxMemoryPolicy struct {
|
||||
// Mode for the set_mempolicy syscall.
|
||||
Mode MemoryPolicyModeType `json:"mode"`
|
||||
|
||||
// Nodes representing the nodemask for the set_mempolicy syscall in comma separated ranges format.
|
||||
// Format: "<node0>-<node1>,<node2>,<node3>-<node4>,..."
|
||||
Nodes string `json:"nodes"`
|
||||
|
||||
// Flags for the set_mempolicy syscall.
|
||||
Flags []MemoryPolicyFlagType `json:"flags,omitempty"`
|
||||
}
|
||||
|
||||
// ZOS contains platform-specific configuration for z/OS based containers.
|
||||
@@ -876,6 +934,26 @@ const (
|
||||
ZOSUTSNamespace ZOSNamespaceType = "uts"
|
||||
)
|
||||
|
||||
type MemoryPolicyModeType string
|
||||
|
||||
const (
|
||||
MpolDefault MemoryPolicyModeType = "MPOL_DEFAULT"
|
||||
MpolBind MemoryPolicyModeType = "MPOL_BIND"
|
||||
MpolInterleave MemoryPolicyModeType = "MPOL_INTERLEAVE"
|
||||
MpolWeightedInterleave MemoryPolicyModeType = "MPOL_WEIGHTED_INTERLEAVE"
|
||||
MpolPreferred MemoryPolicyModeType = "MPOL_PREFERRED"
|
||||
MpolPreferredMany MemoryPolicyModeType = "MPOL_PREFERRED_MANY"
|
||||
MpolLocal MemoryPolicyModeType = "MPOL_LOCAL"
|
||||
)
|
||||
|
||||
type MemoryPolicyFlagType string
|
||||
|
||||
const (
|
||||
MpolFNumaBalancing MemoryPolicyFlagType = "MPOL_F_NUMA_BALANCING"
|
||||
MpolFRelativeNodes MemoryPolicyFlagType = "MPOL_F_RELATIVE_NODES"
|
||||
MpolFStaticNodes MemoryPolicyFlagType = "MPOL_F_STATIC_NODES"
|
||||
)
|
||||
|
||||
// LinuxSchedulerPolicy represents different scheduling policies used with the Linux Scheduler
|
||||
type LinuxSchedulerPolicy string
|
||||
|
||||
@@ -915,3 +993,75 @@ const (
|
||||
// SchedFlagUtilClampMin represents the utilization clamp maximum scheduling flag
|
||||
SchedFlagUtilClampMax LinuxSchedulerFlag = "SCHED_FLAG_UTIL_CLAMP_MAX"
|
||||
)
|
||||
|
||||
// FreeBSD contains platform-specific configuration for FreeBSD based containers.
|
||||
type FreeBSD struct {
|
||||
// Devices which are accessible in the container
|
||||
Devices []FreeBSDDevice `json:"devices,omitempty"`
|
||||
// Jail definition for this container
|
||||
Jail *FreeBSDJail `json:"jail,omitempty"`
|
||||
}
|
||||
|
||||
type FreeBSDDevice struct {
|
||||
// Path to the device, relative to /dev.
|
||||
Path string `json:"path"`
|
||||
// FileMode permission bits for the device.
|
||||
Mode *os.FileMode `json:"mode,omitempty"`
|
||||
}
|
||||
|
||||
// FreeBSDJail describes how to configure the container's jail
|
||||
type FreeBSDJail struct {
|
||||
// Parent jail name - this can be used to share a single vnet
|
||||
// across several containers
|
||||
Parent string `json:"parent,omitempty"`
|
||||
// Whether to use parent UTS names or override in the container
|
||||
Host FreeBSDSharing `json:"host,omitempty"`
|
||||
// IPv4 address sharing for the container
|
||||
Ip4 FreeBSDSharing `json:"ip4,omitempty"`
|
||||
// IPv4 addresses for the container
|
||||
Ip4Addr []string `json:"ip4Addr,omitempty"`
|
||||
// IPv6 address sharing for the container
|
||||
Ip6 FreeBSDSharing `json:"ip6,omitempty"`
|
||||
// IPv6 addresses for the container
|
||||
Ip6Addr []string `json:"ip6Addr,omitempty"`
|
||||
// Which network stack to use for the container
|
||||
Vnet FreeBSDSharing `json:"vnet,omitempty"`
|
||||
// If set, Ip4Addr and Ip6Addr addresses will be added to this interface
|
||||
Interface string `json:"interface,omitempty"`
|
||||
// List interfaces to be moved to the container's vnet
|
||||
VnetInterfaces []string `json:"vnetInterfaces,omitempty"`
|
||||
// SystemV IPC message sharing for the container
|
||||
SysVMsg FreeBSDSharing `json:"sysvmsg,omitempty"`
|
||||
// SystemV semaphore message sharing for the container
|
||||
SysVSem FreeBSDSharing `json:"sysvsem,omitempty"`
|
||||
// SystemV memory sharing for the container
|
||||
SysVShm FreeBSDSharing `json:"sysvshm,omitempty"`
|
||||
// Mount visibility (see jail(8) for details)
|
||||
EnforceStatfs *int `json:"enforceStatfs,omitempty"`
|
||||
// Jail capabilities
|
||||
Allow *FreeBSDJailAllow `json:"allow,omitempty"`
|
||||
}
|
||||
|
||||
// These values are used to control access to features in the container, either
|
||||
// disabling the feature, sharing state with the parent or creating new private
|
||||
// state in the container.
|
||||
type FreeBSDSharing string
|
||||
|
||||
const (
|
||||
FreeBSDShareDisable FreeBSDSharing = "disable"
|
||||
FreeBSDShareNew FreeBSDSharing = "new"
|
||||
FreeBSDShareInherit FreeBSDSharing = "inherit"
|
||||
)
|
||||
|
||||
// FreeBSDJailAllow describes jail capabilities
|
||||
type FreeBSDJailAllow struct {
|
||||
SetHostname bool `json:"setHostname,omitempty"`
|
||||
RawSockets bool `json:"rawSockets,omitempty"`
|
||||
Chflags bool `json:"chflags,omitempty"`
|
||||
Mount []string `json:"mount,omitempty"`
|
||||
Quotas bool `json:"quotas,omitempty"`
|
||||
SocketAf bool `json:"socketAf,omitempty"`
|
||||
Mlock bool `json:"mlock,omitempty"`
|
||||
ReservedPorts bool `json:"reservedPorts,omitempty"`
|
||||
Suser bool `json:"suser,omitempty"`
|
||||
}
|
||||
|
||||
4
vendor/github.com/opencontainers/runtime-spec/specs-go/version.go
generated
vendored
4
vendor/github.com/opencontainers/runtime-spec/specs-go/version.go
generated
vendored
@@ -6,9 +6,9 @@ const (
|
||||
// VersionMajor is for an API incompatible changes
|
||||
VersionMajor = 1
|
||||
// VersionMinor is for functionality in a backwards-compatible manner
|
||||
VersionMinor = 2
|
||||
VersionMinor = 3
|
||||
// VersionPatch is for backwards-compatible bug fixes
|
||||
VersionPatch = 1
|
||||
VersionPatch = 0
|
||||
|
||||
// VersionDev indicates development branch. Releases will be empty string.
|
||||
VersionDev = ""
|
||||
|
||||
2
vendor/modules.txt
vendored
2
vendor/modules.txt
vendored
@@ -67,7 +67,7 @@ github.com/opencontainers/go-digest
|
||||
## explicit; go 1.18
|
||||
github.com/opencontainers/image-spec/specs-go
|
||||
github.com/opencontainers/image-spec/specs-go/v1
|
||||
# github.com/opencontainers/runtime-spec v1.2.1
|
||||
# github.com/opencontainers/runtime-spec v1.3.0
|
||||
## explicit
|
||||
github.com/opencontainers/runtime-spec/specs-go
|
||||
# github.com/pkg/errors v0.9.1
|
||||
|
||||
Reference in New Issue
Block a user